logo

ClickFix Meets AI: A Multi-Platform Attack Targeting macOS in the Wild

ID: 545239e5-5b9b-57bb-b6f3-20ebae630f69

STIX ID: report--545239e5-5b9b-57bb-b6f3-20ebae630f69

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-26

Author: ANY.RUN

...
...

### Executive summary ANY.RUN observed a live macOS ClickFix campaign abusing trust in AI development platforms and search ads to trick users into running terminal commands that deploy the AMOS stealer/backdoor; the malware escalates to root, exfiltrates Keychain data, browser cookies, and crypto wallets, and installs a persistent WebSocket reverse shell, illustrating a high-risk shift in macOS-targeted enterprise attacks and the need for interactive sandbox analysis to detect user-driven execution paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.